Font size
WorksheetsEthical Hacking
Total questions: 90
Worksheet time: 46mins
What is ethical hacking?
Unauthorized system access
Authorized system testing
Malware development
Network disruption
Which type of hacking involves gaining unauthorized access to systems?
White Hat
Black Hat
Grey Hat
Red Hat
What is the primary purpose of ethical hacking?
Data theft
System improvement
Network disruption
Financial gain
Which hacker type operates with permission to test security?
Black Hat
White Hat
Grey Hat
Script Kiddie
What is a disadvantage of ethical hacking?
Improves security
Time-consuming
Always illegal
Guarantees no breaches
Which term refers to exploiting software vulnerabilities?
Phishing
Brute Force
Bug Bounty
Social Engineering
Which tool is commonly used for network scanning in ethical hacking?
Nmap
Photoshop
Excel
Notepad
What is the first phase of ethical hacking?
Reconnaissance
Scanning
Exploitation
Maintaining Access
Which component of the CIA triad ensures data is not altered?
Confidentiality
Integrity
Availability
Authenticity
Under the Indian IT Act 2000, which section deals with hacking?
Section 43
Section 66
Section 67
Section 69
What is a key advantage of ethical hacking?
Data loss
Security enhancement
System crashes
Legal penalties
Which hacker type operates without malicious intent but without permission?
White Hat
Black Hat
Grey Hat
Script Kiddie
What is phishing in ethical hacking terminology?
Network scanning
Social engineering attack
Password cracking
Vulnerability scanning
Which phase of hacking involves gaining access to the target system?
Reconnaissance
Scanning
Exploitation
Covering Tracks
Which skill is essential for ethical hackers?
Graphic design
Penetration testing
Web development
Database management
What does the Indian IT Act 2000 primarily regulate?
Physical security
Cyber activities
Hardware manufacturing
Software licensing
What ensures data is accessible to authorized users in the CIA triad?
Confidentiality
Integrity
Availability
Authentication
Which type of hacking targets sensitive data for malicious purposes?
Ethical Hacking
Black Hat Hacking
Grey Hat Hacking
White Hat Hacking
What is the purpose of the reconnaissance phase in hacking?
Gaining access
Information gathering
System exploitation
Hiding evidence
Which amendment to the Indian IT Act introduced stricter penalties for cybercrimes?
2006
2008
2010
2012
Which tool is used for password cracking in ethical hacking?
Metasploit
John the Ripper
Wireshark
Nessus
What is a script kiddie?
Professional hacker
Novice using pre-written scripts
Authorized tester
Government hacker
Which phase of hacking involves hiding evidence of intrusion?
Scanning
Exploitation
Maintaining Access
Covering Tracks
Which tool is used for vulnerability assessment in ethical hacking?
Burp Suite
Nmap
Nessus
Aircrack-ng
What ensures data is only accessible to authorized users in the CIA triad?
Confidentiality
Integrity
Availability
Non-repudiation
Which section of the Indian IT Act 2000 addresses data protection?
Section 43A
Section 66
Section 67
Section 70
What is a key disadvantage of black hat hacking?
Improves security
Legal consequences
Enhances skills
Authorized access
Which type of hacker may operate for personal gain without permission?
White Hat
Black Hat
Grey Hat
Ethical Hacker
Which tool is used for packet analysis in ethical hacking?
Metasploit
Wireshark
Nessus
John the Ripper
What is the final phase of ethical hacking?
Reconnaissance
Exploitation
Covering Tracks
Reporting
What is reconnaissance in ethical hacking?
Gaining unauthorized access
Information gathering
Exploiting vulnerabilities
Covering tracks
Which type of reconnaissance involves direct interaction with the target?
Passive Reconnaissance
Active Reconnaissance
DNS Enumeration
Banner Grabbing
What is passive reconnaissance?
Scanning network ports
Querying public databases
Exploiting systems
Installing malware
What is footprinting in ethical hacking?
Gaining system access
Collecting target information
Hiding evidence
Cracking passwords
Which tool is commonly used for domain name information gathering?
Nmap
Whois
Metasploit
Wireshark
What does a Whois lookup provide?
IP address ranges
Domain registration details
Website source code
Network traffic data
How can an ethical hacker find the IP address of a website?
Using ping command
Checking browser history
Running a brute force attack
Installing a keylogger
Which service helps identify the hosting company of a website?
DNSenum
Whois
Nmap
Burp Suite
What does IP address range footprinting reveal?
Website content
Network structure
User credentials
Software versions
Which tool is used to view the historical data of a website?
Nmap
Wayback Machine
Wireshark
John the Ripper
What is banner grabbing in fingerprinting?
Capturing network packets
Retrieving service version information
Scanning web applications
Enumerating DNS records
Which protocol is commonly used for banner grabbing?
HTTP
FTP
DNS
ICMP
What is application fingerprinting?
Identifying user accounts
Determining software versions
Scanning network ports
Cracking passwords
Which tool is used for web application scanning?
Nmap
Burp Suite
Whois
DNSenum
What is DNS fingerprinting?
Identifying DNS server versions
Scanning web servers
Capturing network traffic
Exploiting vulnerabilities
What is DNS enumeration?
Scanning network ports
Listing DNS records
Cracking passwords
Hiding tracks
Which tool is used for DNS enumeration?
Nmap
DNSenum
Metasploit
Wireshark
What is a passive reconnaissance technique?
Port scanning
Querying Whois database
Banner grabbing
Vulnerability scanning
Which command-line tool resolves domain names to IP addresses?
nslookup
ping
tracert
netcat
What information can be obtained from the Wayback Machine?
Current website content
Historical website snapshots
Network traffic data
User login details
Which type of reconnaissance avoids detection by not interacting with the target?
Active Reconnaissance
Passive Reconnaissance
DNS Enumeration
Web Scanning
What is the purpose of footprinting in ethical hacking?
Exploit vulnerabilities
Gather target information
Install backdoors
Encrypt data
Which tool can perform both port scanning and banner grabbing?
Nmap
What does a hosting company provide for a website?
Domain name registration
Server infrastructure
Network security
User authentication
Which record type is commonly enumerated in DNS footprinting?
MX
TXT
CNAME
All of the above
What is a limitation of passive reconnaissance?
High detection risk
Limited information depth
Requires system access
Always illegal
Which tool is used for analyzing HTTP responses in web application scanning?
Burp Suite
Nmap
DNSenum
Wireshark
What does the NS record in DNS enumeration indicate?
Mail server
Name server
Canonical name
IP address
Which fingerprinting technique identifies web server software?
Banner Grabbing
DNS Enumeration
Port Scanning
Password Cracking
What is a key benefit of footprinting?
Immediate system access
Detailed target profile
Guaranteed exploits
Hiding tracks
What distinguishes ethical hacking from non-ethical hacking?
Intent and permission
Tools used
Speed of attack
Target selection
Which two phases of hacking are critical for identifying vulnerabilities?
Reconnaissance and Exploitation
Scanning and Enumeration
Exploitation and Covering Tracks
Maintaining Access and Reporting
Which components of the CIA triad are most affected by unauthorized access?
Integrity and Availability
Confidentiality and Integrity
Confidentiality and Availability
Integrity and Authentication
Under the Indian IT Act 2000, which sections address hacking and data breaches?
Sections 43 and 66
Sections 67 and 69
Sections 43A and 70
Sections 66 and 67
What are two key advantages of ethical hacking?
Data theft and system disruption
Security improvement and vulnerability identification
Financial gain and unauthorized access
Malware creation and network crashes
Which two tools are commonly used for network and vulnerability scanning?
Metasploit and John the Ripper
Nmap and Nessus
Wireshark and Burp Suite
Aircrack-ng and Photoshop
What are two key skills required for ethical hacking?
Programming and networking
Graphic design and database management
Web development and social media marketing
Hardware repair and system administration
Which two types of hackers may operate without malicious intent?
Black Hat and Grey Hat
White Hat and Grey Hat
Script Kiddie and Black Hat
White Hat and Script Kiddie
What are two disadvantages of ethical hacking?
Time-consuming and costly
Improves security and prevents breaches
Illegal and unethical
Enhances skills and reduces risks
Which two phases of hacking involve active interaction with the target system?
Reconnaissance and Scanning
Scanning and Exploitation
Exploitation and Maintaining Access
Covering Tracks and Reporting
Which two elements of the Indian IT Act 2000 were strengthened in the 2008 amendment?
Hacking penalties and data protection
Cybercrime definitions and physical security
Software licensing and hardware regulation
Network monitoring and surveillance
What are two common ethical hacking terminologies?
Phishing and Brute Force
Malware and Firewall
Router and Switch
Encryption and Decryption
Which two tools are used for web application testing in ethical hacking?
Burp Suite and OWASP ZAP
Nmap and Wireshark
Nessus and John the Ripper
Metasploit and Aircrack-ng
What are two purposes of ethical hacking?
Identify vulnerabilities and improve security
Steal data and disrupt systems
Create malware and exploit networks
Gain unauthorized access and hide tracks
Which two aspects of the CIA triad are compromised by a DDoS attack?
Integrity and Availability
Confidentiality and Integrity
Confidentiality and Availability
Authentication and Non-repudiation
What are two key differences between active and passive reconnaissance?
Direct interaction vs. no interaction, high vs. low detection risk
Uses same tools, same detection risk
Requires exploits vs. no exploits
Illegal vs. legal
Which two tools are commonly used for footprinting domain name and IP information?
Nmap and Burp Suite
Whois and nslookup
Metasploit and Wireshark
DNSenum and John the Ripper
What are two types of information gathered during footprinting?
Domain registration and IP ranges
User passwords and system exploits
Network traffic and malware signatures
Website content and encryption keys
Which two techniques are used in fingerprinting to identify system details?
Banner Grabbing and Application Fingerprinting
Port Scanning and Password Cracking
DNS Enumeration and Malware Injection
Web Scanning and Brute Forcing
What are two purposes of DNS enumeration?
Identify name servers and mail servers
Crack passwords and gain access
Scan ports and exploit vulnerabilities
Hide tracks and encrypt data
Which two tools are used for web application scanning and fingerprinting?
Burp Suite and OWASP ZAP
Nmap and Whois
DNSenum and Metasploit
Wireshark and John the Ripper
What are two benefits of passive reconnaissance?
Low detection risk and legal
Immediate access and exploits
High accuracy and system control
Requires no tools and fast
Which two types of DNS records are commonly enumerated?
MX and A
TXT and PTR
CNAME and NS
All of the above
What are two limitations of active reconnaissance?
High detection risk and resource-intensive
Limited information and illegal
Requires no tools and slow
Guarantees exploits and access
Which two sources provide historical website data in footprinting?
Wayback Machine and Whois
Nmap and Burp Suite
DNSenum and Wireshark
Metasploit and nslookup
What are two key pieces of information obtained from a Whois lookup?
Domain owner and registrar
IP address and network traffic
Website content and user data
Exploits and vulnerabilities
Which two fingerprinting techniques target web applications?
Web Application Scanning and Application Fingerprinting
Banner Grabbing and DNS Enumeration
Port Scanning and Brute Forcing
DNS Fingerprinting and Malware Analysis
What are two tools used for banner grabbing?
Nmap and Netcat
Whois and DNSenum
Burp Suite and Wireshark
Metasploit and John the Ripper
Which two activities are part of active reconnaissance?
Port scanning and banner grabbing
Querying Whois and using Wayback Machine
DNS enumeration and web scanning
Password cracking and exploit testing
What are two outcomes of effective footprinting?
Detailed network map and vulnerability identification
System access and data theft
Malware installation and track covering
Encryption and authentication
